Important and critical product classes
The CRA categorizes products with digital elements into different risk levels to determine how they must be certified. If a product falls under the "Important" (Annex III) or "Critical" (Annex IV) classes, it is subject to more stringent conformity assessment procedures than standard products.
What it means
The EU distinguishes between products based on their potential impact on security and safety if compromised. While most products can be self-assessed for compliance, those listed in Annexes III and IV are deemed higher risk due to their function or the environment in which they operate (e.g., password managers, network interfaces, or industrial control systems).
In practice, this means that simply declaring compliance is not enough for certain high-risk categories. Depending on whether a product is "Important" or "Critical," the manufacturer may be required to undergo a third-party assessment by a notified body rather than relying solely on internal technical documentation and self-declaration.
How to meet it
- Perform Product Mapping: Review the specific lists in Annex III (Important) and Annex IV (Critical) to determine which category your product falls into based on its intended use and functionality.
- Determine Assessment Path: Identify whether your classification allows for internal control (self-assessment) or mandates a third-party conformity assessment by an EU-recognized notified body.
- Implement Essential Requirements: Ensure the product meets all mandatory cybersecurity requirements outlined in the CRA, as these are non-negotiable regardless of class.
- Establish Technical Documentation: Create detailed records showing how the product was designed and developed to mitigate risks associated with its specific risk class.
- Verify Supply Chain Security: For critical products, implement stricter vetting for third-party components and open-source libraries used in the build.
Evidence an auditor asks for
- Classification Justification Document: A formal record explaining why the product was categorized as "Uncritical," "Important," or "Critical" with references to the Annexes.
- Conformity Assessment Certificate: For Critical products, a certificate issued by a notified body confirming compliance.
- EU Declaration of Conformity: The signed legal document stating the product meets all CRA requirements and specifying its risk class.
- Technical File: Comprehensive documentation including architecture diagrams, vulnerability assessments, and risk management plans specific to that product class.
Common pitfalls
- Under-classification: Intentionally or accidentally classifying a "Critical" product as "Important" or "Uncritical" to avoid the cost and time of third-party audits.
- Static Classification: Failing to re-evaluate the product class when adding new features that might push the device from one category into a higher risk bracket.
- Ignoring Third-Party Timelines: Starting the notified body assessment process too late in the development cycle, leading to delays in market entry (CE marking).